CVE-2024-1892: Scrapy

Medium severity, CVSS 6.5. EPSS: 0.6% chance of exploitation in the next 30 days.

A Regular Expression Denial of Service (ReDoS) vulnerability exists in the XMLFeedSpider class of the scrapy/scrapy project, specifically in the parsing of XML content. By crafting malicious XML content that exploits inefficient regular expression complexity used in the parsing process, an attacker can cause a denial-of-service (DoS) condition. This vulnerability allows for the system to hang and consume significant resources, potentially rendering services that utilize Scrapy for XML processing unresponsive.

Affected products

  • Scrapy Scrapy: before 2.11.1 (fixed in 2.11.1)

Published 2024-02-28. Last modified 2026-06-17.